CVE-2026-18718 is an arbitrary code execution vulnerability in Ghidra’s Swift demangler analysis workflow. The issue resides in the handling of the Swift tool directory path persisted in a Ghidra project. When a project is opened, SwiftDemanglerAnalyzer restores the stored Swift binary directory from project state, and SwiftNativeDemangler subsequently resolves and executes a binary from that location without integrity or signature verification. An attacker can craft a malicious Ghidra project so that the restored Swift tool directory points to attacker-controlled executables. If a victim opens the project, the attacker-controlled binary is executed automatically under the security context of the Ghidra process user, without prompt or confirmation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python entrypoint, CVE-2026-18718-POC.py, plus supporting Markdown documentation (README, classification, source-evidence) and a license. The code is a standalone research/PoC framework, not tied to Metasploit/Nuclei or another common exploit framework. Its primary capability is reproducing the accepted Ghidra Swift demangler arbitrary code execution condition affecting Ghidra <= 12.1.2: if an attacker-controlled Swift tool directory is restored from project/analyzer state, Ghidra resolves and executes a binary named swift-demangle from that directory. The PoC safely simulates this by creating a fake local demangler and, when explicitly enabled with --execute, launching it as Ghidra would; with --launch-calc it can additionally spawn a benign calculator as a visible execution marker. The repository also includes two secondary research modes: tracermi, which scans/source-documents conditional execution sinks in Ghidra TraceRMI debugger agents (execute/eval style methods), and sevenzip, which documents reachability of bundled native SevenZip parsing code from untrusted archive input. Those two modes are evidence/scanning oriented rather than full weaponized exploitation. No network C2, remote callback, or destructive behavior is present. Attack surface is primarily local/file-based: opening or importing attacker-supplied Ghidra content that carries a malicious Swift tool path, or reviewing source trees for additional risky sinks. Overall maturity is operational PoC: it includes a working local execution demonstration and payload marker, but payload behavior is intentionally constrained and safety-gated.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.